The Cybersecurity and Infrastructure Security Agency (CISA) orders federal agencies to patch a critical Oracle WebLogic Server vulnerability.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a three-day deadline for federal agencies to patch a maximum-severity Oracle bug affecting Windows virtual machines. The vulnerability, identified as CVE-2026-21962, allows for improper access control and can grant attackers complete access to all data stored on affected systems. Oracle disclosed the flaw in January 2026, but CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on August 24. The agency noted that the bug has been actively exploited by threat actors since the beginning of the year, including China-linked actors targeting government infrastructure. The flaw affects Oracle's HTTP Server and WebLogic Server Proxy Plug-in. While the vulnerability does not require user interaction, it can lead to a full takeover of the WebLogic Server instance. Organizations are advised to prioritize patching, especially for internet-facing deployments where T3 or IIOP services are reachable from untrusted networks.